-A INPUT -p icmp -m state --state RELATED -j ACCEPT
for things like path MTU discovery, traceroute, ICMP port unreachables, and so on to work properly?
Any downsides of using generic rule like above (if it is needed)?
-- Aleksandar Milivojevic <amilivojevic@xxxxxx> Pollard Banknote Limited Systems Administrator 1499 Buffalo Place Tel: (204) 474-2323 ext 276 Winnipeg, MB R3T 1L7